topview-youtube-kol-ops

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill communicates with an official vendor endpoint (https://mcp.topview.ai) to discover and evaluate YouTube creators. This is consistent with the author's identity and the skill's primary purpose.
  • [SAFE]: No obfuscation, unauthorized data access, or malicious command patterns were detected in the provided files.
  • [SAFE]: The instructions explicitly guide the agent to use the host's internal MCP mechanisms rather than executing local scripts or raw HTTP requests, which reduces the attack surface.
  • [PROMPT_INJECTION]: The skill ingests data from external YouTube profiles and video descriptions. While this represents a surface for indirect prompt injection, the risk is assessed as low since the skill's capabilities are limited to informational research and standard tool calls within the vendor's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 08:58 AM
Security Audit — agent-trust-hub — topview-youtube-kol-ops